* refactor: implement custom ExpoImage wrapper for cache control Add ExpoImage component with automatic cacheKey/cachePath management and replace all expo-image imports across the app * refactor(ios): convert Gekidou to CocoaPods Migrate from Swift Package Manager to CocoaPods, add Keychain write operations, refactor notification handler to remove react-native-notifications headers, and upgrade Swift to 5.0 * npm audit * update fastlane * feat(ci): integrate Intune MAM for enterprise builds with strict OSS protection Add Intune submodule, CI actions, Fastlane configuration, developer scripts, pre-commit hooks, and validation workflows to enable internal MAM builds while protecting OSS repository * fix tests by mocking @mattermost/intune * feat: implement Intune MAM integration with comprehensive security enforcement Add IntuneManager, refactor SecurityManager/SessionManager for MAM policies, implement native OIDC auth flow, add biometric enforcement, conditional launch blocking, and file protection controls * fix alerts when no server database is present * Unify cache strategy * fix emit config changed after it was stored in the db * Handle Mid-Session Enrollment Detection * fix ADALLogOverrideDisabled missing in Fastfile * fix flow for initial enrollment * fix and add unit tests * enable Intune configuration for PR and beta builds, CLIENT_ID should be changed before actual release * Update intune submodule with addressed feedback * fix validate-intune-clean workflow * feat(intune): add comprehensive error handling and SAML+Entra support Add production-ready error handling for native Entra authentication with user-friendly i18n messages, comprehensive test coverage, and support for Entra login when server requires SAML. * update i18n * update intune submodule * update build-pr token * fix race condition between server auth and intune enrollment * fix CI workflow to build with intune * use deploy key for intune submodule * set the config directly in the submodule .git * debug injection * try setting GIT_SSH_COMMAND * remove action debug * fix server url input * match pod cache with intune hash * Fastfile and envs * have workflows check for intune/.git * have ci cache intune frameworks as well * update Fastlane to set no-cache to artifacts uploaded * fix s3 upload * fix pblist template * Attempt to remove the cache control for PR uploads to s3 * use hash from commit for S3 path * Implement crash-resilient selective wipe with automatic retry and add removeInternetPassword to Gekidou Keychain * Fix surface errors from intune login * fix postinstall scripts * use cacheKey for draft md images * remove unnecessary double await during test * Have isMinimumLicenseTier accept valid license sku tier as target * Add missing Auth error messages * remove the last period for intune errors in i18n * do not call unenroll with wipe on manual logout * Fix tests and Intune error messages * do not filter any SSO type regardless of which is used for Intune * fix 412 to not retry * fix tests, app logs sharing and share_extension avatar cache * apply setScreenCapturePolicy on license change Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * re-apply screen capture on enrollment Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * use userData from intunr login and prevent getMe Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com> * Check for Biometrics and Jailbreak as we used to --------- Co-authored-by: Eva Sarafianou <eva.sarafianou@mattermost.com>
62 lines
2.1 KiB
YAML
62 lines
2.1 KiB
YAML
name: prepare-ios-build
|
|
description: Action to prepare environment for ios build
|
|
|
|
inputs:
|
|
intune-enabled:
|
|
description: 'Enable Intune MAM features (requires Xcode 26.1+)'
|
|
required: false
|
|
default: 'false'
|
|
intune-ssh-private-key:
|
|
description: 'SSH private key for Intune submodule repository access (required if intune-enabled is true)'
|
|
required: false
|
|
|
|
runs:
|
|
using: composite
|
|
steps:
|
|
- name: ci/setup-xcode
|
|
uses: maxim-lobanov/setup-xcode@60606e260d2fc5762a71e64e74b2174e8ea3c8bd # v1.6.0
|
|
with:
|
|
xcode-version: '26.1'
|
|
|
|
- name: ci/prepare-mobile-build
|
|
uses: ./.github/actions/prepare-mobile-build
|
|
|
|
- name: ci/setup-intune
|
|
if: inputs.intune-enabled == 'true'
|
|
uses: ./.github/actions/setup-intune
|
|
with:
|
|
ssh-private-key: ${{ inputs.intune-ssh-private-key }}
|
|
|
|
- name: Get Intune submodule commit hash
|
|
if: inputs.intune-enabled == 'true'
|
|
id: intune-hash
|
|
shell: bash
|
|
run: |
|
|
if [ -e "libraries/@mattermost/intune/.git" ]; then
|
|
INTUNE_HASH=$(cd libraries/@mattermost/intune && git rev-parse --short HEAD)
|
|
echo "hash=${INTUNE_HASH}" >> $GITHUB_OUTPUT
|
|
else
|
|
echo "hash=none" >> $GITHUB_OUTPUT
|
|
fi
|
|
|
|
- name: Cache Pods
|
|
uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4.2.3
|
|
with:
|
|
path: |
|
|
ios/Pods
|
|
libraries/@mattermost/intune/ios/Frameworks
|
|
key: ${{ runner.os }}-pods-v3-intune-${{ inputs.intune-enabled }}-${{ steps.intune-hash.outputs.hash }}-${{ hashFiles('ios/Podfile.lock') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-pods-v3-intune-${{ inputs.intune-enabled }}-${{ steps.intune-hash.outputs.hash }}-
|
|
${{ runner.os }}-pods-v3-intune-${{ inputs.intune-enabled }}-
|
|
|
|
- name: ci/install-pods-dependencies
|
|
shell: bash
|
|
env:
|
|
INTUNE_ENABLED: ${{ inputs.intune-enabled == 'true' && '1' || '0' }}
|
|
run: |
|
|
echo "::group::install-pods-dependencies"
|
|
echo "INTUNE_ENABLED=$INTUNE_ENABLED"
|
|
npm run ios-gems
|
|
npm run pod-install
|
|
echo "::endgroup::"
|